It begins with a boundary: A geometric view on probabilistically robust learning

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Bungert, Leon, Trillos, Nicolás García, Jacobs, Matt, McKenzie, Daniel, Nikolić, Đorđe, Wang, Qingsong
Natura: Preprint
Pubblicazione: 2023
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866912050642419712
author Bungert, Leon
Trillos, Nicolás García
Jacobs, Matt
McKenzie, Daniel
Nikolić, Đorđe
Wang, Qingsong
author_facet Bungert, Leon
Trillos, Nicolás García
Jacobs, Matt
McKenzie, Daniel
Nikolić, Đorđe
Wang, Qingsong
contents Although deep neural networks have achieved super-human performance on many classification tasks, they often exhibit a worrying lack of robustness towards adversarially generated examples. Thus, considerable effort has been invested into reformulating standard Risk Minimization (RM) into an adversarially robust framework. Recently, attention has shifted towards approaches which interpolate between the robustness offered by adversarial training and the higher clean accuracy and faster training times of RM. In this paper, we take a fresh and geometric view on one such method -- Probabilistically Robust Learning (PRL). We propose a mathematical framework for understanding PRL, which allows us to identify geometric pathologies in its original formulation and to introduce a family of probabilistic nonlocal perimeter functionals to rectify them. We prove existence of solutions to the original and modified problems using novel relaxation methods and also study properties, as well as local limits, of the introduced perimeters. We also clarify, through a suitable $Γ$-convergence analysis, the way in which the original and modified PRL models interpolate between risk minimization and adversarial training.
format Preprint
id arxiv_https___arxiv_org_abs_2305_18779
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle It begins with a boundary: A geometric view on probabilistically robust learning
Bungert, Leon
Trillos, Nicolás García
Jacobs, Matt
McKenzie, Daniel
Nikolić, Đorđe
Wang, Qingsong
Machine Learning
Analysis of PDEs
Optimization and Control
Although deep neural networks have achieved super-human performance on many classification tasks, they often exhibit a worrying lack of robustness towards adversarially generated examples. Thus, considerable effort has been invested into reformulating standard Risk Minimization (RM) into an adversarially robust framework. Recently, attention has shifted towards approaches which interpolate between the robustness offered by adversarial training and the higher clean accuracy and faster training times of RM. In this paper, we take a fresh and geometric view on one such method -- Probabilistically Robust Learning (PRL). We propose a mathematical framework for understanding PRL, which allows us to identify geometric pathologies in its original formulation and to introduce a family of probabilistic nonlocal perimeter functionals to rectify them. We prove existence of solutions to the original and modified problems using novel relaxation methods and also study properties, as well as local limits, of the introduced perimeters. We also clarify, through a suitable $Γ$-convergence analysis, the way in which the original and modified PRL models interpolate between risk minimization and adversarial training.
title It begins with a boundary: A geometric view on probabilistically robust learning
topic Machine Learning
Analysis of PDEs
Optimization and Control
url https://arxiv.org/abs/2305.18779